CHAPTER IIIRIGHTS OF THE DATA SUBJECT

Article 21Right to object

Official text

(1)The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1), including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.

(2)Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.

(3)Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.

(4)At the latest at the time of the first communication with the data subject, the right referred to in paragraphs 1 and 2 shall be explicitly brought to the attention of the data subject and shall be presented clearly and separately from any other information.

(5)In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, the data subject may exercise his or her right to object by automated means using technical specifications.

(6)Where personal data are processed for scientific or historical research purposes or statistical purposes pursuant to Article 89(1), the data subject, on grounds relating to his or her particular situation, shall have the right to object to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

Commentary

18. Article 21(2) GDPR - Absolute Right to Object to Direct Marketing

Article 21(2) creates a particularly strong form of the right to object where personal data are processed for direct marketing purposes.

It provides:

“Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.”

This provision must be distinguished carefully from Article 21(1).

Under Article 21(1), the data subject generally has to identify grounds relating to his or her particular situation. The controller may continue processing if it demonstrates compelling legitimate grounds that override the interests, rights and freedoms of the individual.

Article 21(2) operates differently.

Where the processing concerns direct marketing, the data subject does not have to establish a particular situation. The individual does not have to prove that the marketing causes harm, creates a privacy risk, interferes with a fundamental right, or is otherwise unreasonable.

The objection itself is sufficient.

18.1 No requirement to provide reasons

The individual does not have to explain why he or she no longer wants marketing.

Example

suppose an online retailer sends promotional emails to a customer. The customer clicks "unsubscribe" or otherwise communicates an objection.

The customer does not need to say:

  • "I consider your marketing intrusive";

  • "Your profiling interferes with my privacy";

  • "I have received too many emails";

  • "I have a particular personal circumstance that makes marketing inappropriate."

The objection is sufficient.

18.2 No balancing exercise after objection

This is one of the most important features of Article 21(2).

A controller cannot respond:

"Our legitimate commercial interests outweigh your objection."

That type of balancing exercise belongs to Article 21(1), not Article 21(2).

Similarly, the controller cannot normally justify continued direct marketing merely by relying upon:

  • commercial necessity;

  • increased customer engagement;

  • business profitability;

  • personalised customer experience;

  • advertising efficiency;

  • legitimate interests.

Once the individual objects to processing for direct marketing purposes, the controller must cease that processing.

18.3 Why the provision is described as "absolute"

The right is commonly described as absolute because the controller has no overriding-interest defence comparable to Article 21(1).

The strength of the provision reflects a policy judgment within the GDPR:

An individual should not be forced to receive personalised commercial communications merely because an organisation considers those communications commercially beneficial.

The individual's choice therefore takes precedence over the controller's marketing interest.

18.4 Example

Assume an online fashion platform analyses a customer's purchases and browsing history and sends personalised advertisements recommending clothing.

The customer objects to direct marketing.

The company cannot argue:

"The customer has purchased from us previously, therefore we have a strong legitimate interest in continuing personalised marketing."

That argument cannot defeat an Article 21(2) objection.

The marketing processing must stop.

19. Why Direct Marketing Receives Stronger Protection

Direct marketing receives particularly strong protection because it involves more than merely storing or using personal information.

Marketing frequently involves the use of personal information to influence an individual's behaviour.

Traditional advertising may involve communicating the same message to a large audience. Modern digital marketing, however, increasingly relies upon personal information to determine:

  • what advertisement a person sees;

  • when the advertisement is shown;

  • which products are recommended;

  • what price or offer is presented;

  • what content is likely to generate engagement;

  • which characteristics are associated with purchasing behaviour.

Consequently, marketing can become closely connected with profiling and behavioural surveillance.

19.1 Behavioural tracking

An organisation may monitor:

  • pages visited;

  • products viewed;

  • searches performed;

  • advertisements clicked;

  • time spent on particular pages;

  • previous purchases.

This information can be combined to construct a detailed behavioural profile.

19.2 Purchasing histories

A person's previous purchases can reveal interests and preferences.

Example

repeated purchases of:

  • children's products may indicate the presence of children in a household;

  • medical products may reveal information about health;

  • books may reveal intellectual or political interests;

  • financial products may indicate financial circumstances.

When this information is used to personalise advertising, the marketing activity can become substantially more intrusive than ordinary advertising.

19.3 Location analysis

Location data can also be used to personalise advertising.

Example

an advertising system might infer that a person regularly visits:

  • gyms;

  • hospitals;

  • universities;

  • luxury shopping districts;

  • religious institutions;

  • particular entertainment venues.

Such information can contribute to extensive behavioural profiles.

19.4 Predictive advertising

Modern advertising systems may go beyond analysing what a person has already done.

They may attempt to predict:

  • what the person will purchase;

  • what the person is interested in;

  • when the person is likely to make a purchase;

  • which advertisement is most likely to persuade the person.

Article 21(2) is therefore particularly important in an environment where marketing increasingly depends upon algorithmic profiling.

20. Meaning of Direct Marketing

The GDPR does not provide a single comprehensive statutory definition of "direct marketing" in Article 21.

The concept should nevertheless be understood broadly in light of the purpose of the provision.

Direct marketing generally involves communication or promotional activity directed toward an identifiable individual or group with the objective of promoting:

  • goods;

  • services;

  • commercial relationships;

  • personalised offers;

  • fundraising activities;

  • products or services of the organisation or third parties.

Examples

include:

Promotional emails

An online retailer sends:

"20% off all shoes this weekend."

This is a straightforward example of direct marketing.

SMS advertising

A company sends a customer:

"Exclusive offer: Get ₹500 off your next purchase."

The communication is promotional and directed at the individual.

Telephone marketing

A company contacts a person by telephone to promote a service or product.

Postal marketing

A business sends promotional material to an individual's physical address.

Personalised recommendations

A streaming service recommends particular content based on a user's previous behaviour.

The precise legal classification may depend on the circumstances, but where the recommendation forms part of a marketing activity, Article 21(2) may become relevant.

Targeted online advertising

An advertising platform may use personal information to determine which advertisement should be shown to an individual.

The central question is therefore not simply whether the communication is commercial, but whether personal data are being processed for a marketing purpose directed toward the individual.

21. Direct Marketing Is Not Limited to the Controller's Own Products

Another important point is that direct marketing is not restricted to marketing the controller's own products or services.

A controller may process personal data in order to facilitate marketing on behalf of another organisation.

Example

assume:

Company A operates an online shopping platform.

Company B sells insurance.

Company A uses information about its customers to identify people who may be interested in Company B's insurance products.

The resulting marketing activity may fall within the concept of direct marketing even though Company A is not selling its own insurance product.

21.1 Affiliate marketing

Affiliate marketing may involve sharing or using personal data to promote products belonging to another organisation.

The fact that the commercial relationship involves multiple organisations does not remove the individual's Article 21 protection.

21.2 Advertising partnerships

Companies may cooperate with advertising partners to target particular users.

For example:

Retailer → advertising platform → personalised advertisement.

The existence of several organisations in the processing chain does not itself eliminate the right to object.

21.3 Third-party campaigns

A company may also process its customer database to promote third-party services.

Example

a financial platform might use customer information to promote insurance products supplied by an external insurer.

The individual's right to object remains relevant to the processing undertaken for direct marketing.

Article 21(2) expressly extends the right to objection to profiling, but only to the extent that the profiling is related to direct marketing.

This is extremely significant in the modern digital economy.

Profiling is particularly important because marketing decisions are increasingly made by algorithms rather than humans.

A marketing system may analyse:

  • browsing history;

  • search behaviour;

  • purchase history;

  • location;

  • demographic information;

  • interaction with advertisements;

  • previous responses to promotional communications.

The system may then infer:

  • interests;

  • preferences;

  • purchasing likelihood;

  • likely responsiveness to particular advertisements.

The resulting profile can determine which marketing communication an individual receives.

Example

Suppose an online platform observes that a user repeatedly searches for:

  • running shoes;
  • fitness equipment;
  • marathon training;
  • sports watches. An algorithm may classify the individual as a:

"high-probability fitness customer."

The platform then sends personalised advertisements for expensive sports products.

If that profiling is being carried out for direct marketing, Article 21(2) permits the individual to object to that processing.

Importance

The provision is therefore not limited to the final communication.

It can reach the profiling process underlying the communication.

This is important because simply stopping the final email while continuing to build the marketing profile would undermine the practical purpose of the right.

23. Limitation: Profiling Must Be Connected to Marketing

Article 21(2) does not mean that every form of profiling automatically becomes subject to the absolute marketing objection.

The wording is deliberately limited:

profiling "to the extent that it is related to such direct marketing."

The connection between the profiling and marketing is therefore important.

Example 1

Fraud detection A bank analyses transaction patterns to detect fraudulent activity. The bank may create behavioural profiles for security purposes. This is not necessarily direct marketing. The fact that profiling occurs does not automatically make Article 21(2) applicable. Other provisions, including Article 21(1), may become relevant depending on the legal basis and circumstances.

Example 2

Product recommendations Suppose the same bank analyses customer behaviour to determine which premium financial product should be promoted to the customer. Here, the profiling has a clear promotional objective. The processing may therefore fall within Article 21(2).

Practical distinction

The controller should therefore identify:

  1. why the profiling occurs;

  2. what purpose the profile serves;

  3. whether the profile is used to promote goods or services;

  4. whether the resulting activity constitutes direct marketing.

The mere presence of an algorithm is not sufficient.

The purpose and connection with marketing matter.

24. Effect of Objection Under Article 21(3)

Article 21(3) gives practical effect to Article 21(2).

It provides:

"Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes."

The provision therefore creates a direct consequence following an objection.

The controller must stop processing the personal data for the relevant marketing purpose.

This may require changes across several systems.

24.1 Stopping marketing communications

The organisation must stop sending:

  • promotional emails;

  • marketing SMS;

  • promotional notifications;

  • direct-mail campaigns;

  • marketing calls.

24.2 Stopping marketing profiling

The organisation should also stop using the person's personal data to construct or maintain profiles for direct marketing purposes where necessary to give effect to the objection.

Simply stopping one email while continuing the underlying marketing profile may not adequately respect the objection.

24.3 Stopping targeted advertising

Where the controller itself processes personal data to target advertising, the relevant processing must cease following an objection.

24.4 Stopping promotional analysis

If customer data are being analysed specifically to determine which promotional material should be sent to the individual, that marketing-related processing should also be addressed.

The central principle is:

The objection must be effective in substance, not merely acknowledged formally.

25. Processing for Other Purposes May Continue

Article 21(3) does not necessarily require the complete deletion of the individual's personal data.

This distinction is crucial.

An objection to marketing processing is not automatically a request for erasure under Article 17.

The same personal data may be processed for several independent purposes.

Example

A customer purchases a laptop from an online retailer. The retailer may hold:

  • billing information;
  • transaction records;
  • warranty information;
  • delivery records;
  • customer-service records.

The customer later objects to promotional emails.

The retailer must stop marketing processing.

However, it may still retain information necessary for:

  • accounting;

  • tax compliance;

  • warranty obligations;

  • dispute resolution;

  • contractual records.

The objection therefore operates according to purpose.

Purpose limitation

This illustrates the GDPR principle of purpose limitation.

The controller should distinguish between:

processing for marketing

and

processing for another lawful purpose.

The objection terminates or restricts the former; it does not automatically destroy the legal basis for the latter.

26. Marketing Suppression Lists

One of the most important practical issues arising after a marketing objection is the use of a marketing suppression list.

Consider the following situation.

A person objects to marketing.

The company deletes the person's entire customer profile.

Six months later, the company obtains the person's email address again through another lawful source and sends another promotional email.

The company has effectively defeated the original objection.

A suppression mechanism can prevent this.

26.1 Purpose of a suppression list

A suppression list contains limited information necessary to ensure that an individual who has objected is not accidentally marketed to again.

For example:

  • email address;

  • telephone number;

  • objection status;

  • date of objection.

The organisation does not necessarily need to retain the entire customer profile.

26.2 Data minimisation

The suppression list should itself comply with GDPR principles.

The controller should retain only what is necessary to honour the objection.

Example

it may be unnecessary to retain:

  • complete purchasing history;

  • browsing history;

  • detailed customer profile;

  • demographic information.

The organisation may only need the identifier necessary to prevent future marketing.

26.3 Balancing erasure and compliance

This creates an important distinction:

Deletion of unnecessary data does not mean deletion of information necessary to honour a legal objection.

The organisation should therefore design its systems so that erasure requests and marketing objections can operate together.

Direct marketing can be supported by different legal mechanisms depending on the circumstances.

The source material identifies:

  • consent;

  • legitimate interest;

  • other lawful bases.

The existence of a lawful basis, however, does not remove Article 21(2).

27.1 Marketing based on legitimate interest

Suppose a company relies on legitimate interest to send promotional communications.

The customer objects.

The company cannot respond:

"We have already completed a legitimate-interest assessment, therefore you cannot object."

Article 21(2) provides a specific and stronger protection for direct marketing.

Where marketing depends upon consent, the individual may withdraw that consent.

The practical result is also that the relevant marketing processing must stop.

However, conceptually, the two mechanisms should not be confused:

Withdrawal of consent operates through the withdrawal of the legal basis under Article 7.

Objection to direct marketing operates through Article 21(2).

27.3 Why the distinction matters

A controller should therefore identify the actual legal mechanism being exercised.

The organisation's compliance procedure should be capable of recognising:

  • consent withdrawal;

  • Article 21 marketing objection;

  • Article 21(1) objection;

  • Article 17 erasure request.

These are related but legally distinct rights.

28. CJEU Jurisprudence on Direct Marketing

Judicial interpretation is particularly important in the field of digital marketing because technology develops much faster than statutory terminology.

The source material identifies two important decisions:

  • StWL Städtische Werke Lauf (C-102/20)

  • Planet49 (C-673/17)

These cases demonstrate the importance of interpreting privacy and electronic communications law in a technologically neutral manner.

28.1 StWL Städtische Werke Lauf (C-102/20)

The case concerned advertising displayed within an email inbox.

The legal question involved whether such advertising could constitute electronic mail for purposes of the applicable privacy framework.

The importance of the case extends beyond the specific technology.

It demonstrates that organisations should not be able to escape privacy protections simply by designing a new technical method for delivering advertisements.

Technological neutrality

If the law protected only traditional advertising emails, an organisation could potentially design a functionally identical advertising mechanism that technically avoided the statutory category.

That would produce an undesirable result:

privacy protection would depend upon the technical architecture used to deliver the advertisement.

The Court's approach therefore supports a functional understanding of communications.

Practical significance

The case is particularly relevant to:

  • inbox advertising;

  • personalised advertisements;

  • platform advertising;

  • emerging digital marketing techniques;

  • algorithmically selected commercial content.

The underlying principle is that technological innovation should not automatically eliminate privacy protection.

28.2 Planet49 (C-673/17)

Planet49 is particularly significant for the relationship between online advertising, cookies and consent.

Although the case was primarily concerned with cookies and consent rather than Article 21 itself, its principles are highly relevant to the broader philosophy of individual control.

The judgment emphasised:

  • transparency;

  • genuine choice;

  • active user control.

An individual should not be considered to have consented merely because he or she remained inactive.

Importance for marketing

Modern marketing frequently depends upon tracking technologies.

If an organisation can obtain extensive behavioural information merely because a user fails to take action, the individual's control becomes largely theoretical.

The principles reflected in Planet49 therefore reinforce the broader GDPR objective that individuals should have meaningful control over the use of their personal information.

29. Article 21(4) - Obligation to Inform About the Right to Object

Article 21(4) introduces a specific transparency obligation.

It requires that the right referred to in Article 21(1) and Article 21(2) be:

"explicitly brought to the attention of the data subject"

and this must occur at the latest at the time of the first communication.

This is more than a general transparency requirement.

The controller must actively draw the individual's attention to the right.

Why this matters

A right is of limited practical value if individuals do not know that it exists.

Therefore, Article 21(4) seeks to prevent controllers from technically providing information while practically hiding the right.

The right should not be buried in:

  • lengthy privacy notices;

  • complicated legal documents;

  • general terms and conditions;

  • extensive contractual documentation.

The individual should be able to identify the right easily.

30. Meaning of "Explicitly"

The requirement that the right be communicated "explicitly" is significant.

A vague statement such as:

"You may have rights under applicable data protection law."

would provide little meaningful information.

It does not tell the individual:

  • what the right is;

  • when it applies;

  • how it can be exercised.

A stronger communication would state:

"You have the right to object at any time to the processing of your personal data for direct marketing purposes."

This tells the person precisely:

  1. that the right exists;

  2. what processing it concerns;

  3. that the right can be exercised at any time.

The purpose of Article 21(4) is therefore not merely formal disclosure.

It seeks to create effective awareness.

31. Meaning of "Clearly and Separately"

The right must also be presented clearly and separately.

This requirement reflects the GDPR's broader emphasis on understandable information.

A controller should avoid presenting the right as one sentence hidden among dozens of unrelated provisions.

Poor approach

A privacy notice contains several pages concerning:

  • cookies;

  • analytics;

  • data transfers;

  • retention;

  • security;

  • processors;

  • legal bases;

and the right to object appears in the middle of a dense paragraph.

Although technically present, the information may not be sufficiently prominent.

Better approach

The controller could provide:

Your right to object

You may object at any time to the processing of your personal data for direct marketing purposes.

A dedicated:

"Unsubscribe"

or

"Manage marketing preferences"

link can make the right immediately accessible.

Practical implementation

Good practices include:

  • separate paragraphs;

  • dedicated headings;

  • prominent notices;

  • one-click opt-out mechanisms;

  • preference centres;

  • easily accessible unsubscribe links.

32. Timing Requirement

Article 21(4) imposes a specific temporal requirement.

The right must be communicated:

at the latest at the time of the first communication.

This means that an organisation should not send several marketing communications and only later inform the individual about the right to object.

Example

Suppose Company X sends a promotional email to a customer for the first time. That first email should already make the individual aware of the right to object. A practical implementation could be: "You may object to receiving marketing communications at any time. Click here to unsubscribe." The timing requirement ensures that the right exists in a practical sensefrom the beginning of the marketing relationship.

33. Relationship with Articles 13 and 14

Article 21(4) should be read together with Articles 13 and 14.

Articles 13 and 14 contain transparency requirements concerning the right to object.

Therefore, there may be two important moments for communication.

First stage - Collection

When personal data are collected, the controller should provide the required information concerning the individual's rights.

Thus:

Collection of data → information about objection rights.

Second stage - First marketing communication

Where direct marketing subsequently occurs, Article 21(4) requires that the right be brought explicitly to the individual's attention no later than the first communication.

Thus:

First marketing communication → explicit reminder of the right.

The second communication is important because an individual who originally provided information for one reason may later encounter marketing processing in a different context.

34. Article 21(5) - Automated Exercise of the Right to Object

Article 21(5) reflects the reality of digital services.

It provides that, in the context of information society services, the data subject may exercise the right to object by automated means using technical specifications.

This is an important procedural principle.

A right should not become practically useless because exercising it requires excessive human interaction.

Traditional model

An individual might have to:

  1. find the company's contact information;

  2. write an email;

  3. identify the relevant processing;

  4. wait for customer service;

  5. answer verification questions;

  6. wait for confirmation.

This creates friction.

Automated model

Instead, the individual could:

  1. click "unsubscribe";

  2. select a privacy preference;

  3. activate a technical objection signal;

  4. automatically communicate the individual's preference.

The law therefore recognises that technology can facilitate the exercise of rights.

35. Examples of Automated Objection Mechanisms

35.1 Email unsubscribe systems

A one-click unsubscribe mechanism is perhaps the simplest example.

The user receives:

"Unsubscribe from marketing."

The individual clicks once.

The marketing preference is updated automatically.

This is preferable to requiring the user to send a separate email.

35.2 Browser signals

Technical signals may communicate privacy preferences automatically.

The broader concept is that a user's technological environment can communicate an objection or preference to online services.

The effectiveness of such mechanisms depends upon technical compatibility and the legal framework applicable to the particular signal.

35.3 Privacy preference tools

A platform may provide a central privacy dashboard where the individual can select:

"Do not use my information for personalised advertising."

The platform can automatically update the relevant processing preferences.

35.4 Platform privacy settings

Large online services may allow users to configure:

  • personalised advertising;

  • marketing communications;

  • promotional notifications;

  • data-sharing preferences.

The more directly the setting communicates the user's decision, the more meaningful the right becomes.

36. Importance for Online Platforms

Article 21(5) is particularly important for large digital platforms because they process data at enormous scale.

Imagine a platform with millions of users.

If every individual had to send a separate email to exercise a marketing objection, the process would be inefficient for both:

  • the individual; and

  • the controller.

Automated systems can make privacy rights scalable.

Benefits include:

Accessibility

Individuals can exercise rights quickly.

Consistency

The same mechanism can apply across millions of accounts.

Speed

The preference can be implemented immediately or rapidly.

Reduced administrative burden

Controllers do not have to process every objection manually.

Interoperability

Standardised technical mechanisms may allow privacy preferences to travel more efficiently across digital services.

This is particularly relevant to:

  • social media platforms;

  • search engines;

  • advertising networks;

  • streaming platforms;

  • online marketplaces.

37. Article 21(6) - Research, Historical and Statistical Processing

Article 21(6) introduces a specialised rule for processing carried out for:

  • scientific research;

  • historical research;

  • statistical purposes.

The provision recognises that research processing can have substantial public and societal value.

At the same time, research can involve extensive processing of personal information.

The GDPR therefore attempts to balance two interests:

Individual autonomy

against

the social value of research.

Unlike Article 21(2), this is not an absolute marketing-style objection.

The structure is closer to the balancing logic of Article 21(1), subject to the specific statutory conditions.

38. Conditions Under Article 21(6)

Under Article 21(6), the individual may object on grounds relating to his or her particular situation.

This is therefore an important distinction.

The individual cannot simply say:

"I object because this is research."

Instead, the individual must identify grounds connected to his or her particular circumstances.

Public-interest limitation

The right does not apply where processing is necessary for the performance of a task carried out for reasons of public interest.

This reflects the recognition that some research activities may serve significant collective interests.

Example

A government-supported epidemiological study analyses population-level disease patterns. The study may involve processing personal data under an appropriate legal framework. If the processing is necessary for a public-interest task, Article 21(6) may limit the ability to object. The exception should nevertheless be understood carefully: it does not mean that every activity labelled "research" automatically escapes individual rights. The statutory conditions and applicable safeguards remain important.

39. Relationship with Article 89 GDPR

Article 21(6) should be understood together with Article 89.

Article 89 addresses safeguards and derogations relating to processing for:

  • archiving in the public interest;

  • scientific research;

  • historical research;

  • statistical purposes.

The GDPR recognises that research may require processing datasets that would otherwise be difficult to use under ordinary data-processing constraints.

However, this flexibility is accompanied by safeguards.

The source material identifies measures such as:

  • technical safeguards;

  • organisational safeguards;

  • pseudonymisation;

  • data minimisation.

The underlying balance

The GDPR does not treat research as either:

"completely exempt from privacy law"

or

"completely prohibited."

Instead, it attempts to create a framework where valuable research can occur while reducing unnecessary interference with individual privacy.

40. Examples of Research Processing

Research processing may include:

Medical research

Researchers may analyse health information to investigate diseases or evaluate treatments.

Epidemiological research

Researchers may analyse population-level data to identify disease patterns.

Climate research

Large datasets may be analysed to study environmental trends.

Historical research

Archives may contain information concerning individuals from earlier periods.

Statistical research

Personal information may be aggregated and analysed to identify societal patterns.

In each case, the relevant legal basis, safeguards and specific statutory requirements must be considered.

41. Public Interest Exception

The public-interest element is important because certain research activities may produce benefits that extend beyond the individual whose data are being processed.

Example

a public-health authority may conduct a study designed to understand the spread of disease.

The purpose may include:

  • identifying disease patterns;

  • planning public-health interventions;

  • allocating healthcare resources;

  • identifying emerging risks.

Where the processing is genuinely necessary for a public-interest task, Article 21(6) can restrict the individual's objection.

The exception therefore reflects a fundamental GDPR principle:

Individual rights are strong, but they operate within a broader legal framework that also recognises legitimate collective interests.

The controller should nevertheless be able to explain:

  • why the research is necessary;

  • why the particular processing is necessary;

  • what safeguards are in place;

  • why the public-interest basis applies.

42. Article 21 and Artificial Intelligence Governance

Article 21 has increasing importance in the context of artificial intelligence.

Modern AI systems frequently rely upon:

  • large datasets;

  • behavioural analysis;

  • profiling;

  • predictive models;

  • legitimate-interest assessments;

  • automated decision-support systems.

AI can therefore create situations in which individuals have limited visibility into how their personal data influence algorithmic outcomes.

Examples

include:

  • recommendation systems;
  • recruitment algorithms;
  • credit-scoring systems;
  • facial-recognition technologies;
  • predictive systems;
  • personalised advertising. Article 21 becomes particularly relevant where AI-driven processing relies upon a legal basis that permits objection.

Why AI makes the right more important

Traditional data processing may involve a relatively simple activity:

"Company stores customer's email address."

AI systems can perform much more complex processing:

"System analyses thousands of data points and predicts that this individual is likely to behave in a particular way."

The second situation raises much greater concerns regarding:

  • autonomy;

  • transparency;

  • profiling;

  • discrimination;

  • behavioural influence.

43. AI Profiling and Individual Control

One of the distinctive features of AI is its ability to infer information that an individual never directly supplied.

Example

an AI system may infer:

  • political interests;

  • financial reliability;

  • health-related risks;

  • personality characteristics;

  • purchasing preferences.

The individual may never have expressly stated any of these characteristics.

Example

An AI system analyses:

  • browsing behaviour;
  • purchasing history;
  • online activity;
  • interaction patterns. It concludes:

"This person is highly likely to purchase premium financial products."

The person never provided that conclusion directly.

The AI nevertheless creates a profile about the individual.

This illustrates why the right to object can be important in algorithmic environments.

Important

limitation Article 21 should not be treated as a universal right to prohibit every AI system. Its application depends upon:

  • the legal basis;
  • the purpose of processing;
  • whether Article 21(1) or 21(2) applies;
  • whether an applicable exception exists;

  • whether another GDPR provision governs the processing.

44. AI and Legitimate Interest Assessment

Where an AI system relies upon legitimate interests, the controller should carefully evaluate the impact of the processing.

Relevant assessments may include:

  • legitimate interest assessments;

  • DPIAs where required;

  • fundamental-rights impact assessments where appropriate.

A controller should consider:

  1. What legitimate interest is being pursued?

  2. Is the AI processing necessary?

  3. Could the objective be achieved using less intrusive means?

  4. What reasonable expectations does the individual have?

  5. What personal data are being processed?

  6. What inferences are being generated?

  7. How significant are the consequences?

  8. What safeguards exist?

Objection should trigger reassessment

An objection should not necessarily be treated as a meaningless administrative event.

Where Article 21(1) applies, the objection requires the controller to consider whether its interests are sufficiently compelling to continue the processing.

The controller therefore cannot simply say:

"The AI system is efficient."

Efficiency alone does not automatically establish that processing should override the individual's interests, rights and freedoms.

45. Comparison with India's DPDP Act, 2023

A significant difference exists between the GDPR and India's Digital Personal Data Protection Act, 2023.

The source material identifies that the DPDP Act does not contain an equivalent general right to object comparable to Article 21 GDPR.

This is an important structural distinction.

GDPR approach

The GDPR expressly recognises:

  • a general right to object in specified circumstances;

  • a right to object to certain profiling;

  • an especially strong right to object to direct marketing.

This gives the individual an explicit mechanism to challenge certain ongoing processing even where the processing may otherwise have a lawful basis.

DPDP Act approach

The DPDP Act primarily provides mechanisms such as:

  • access;

  • correction;

  • erasure;

  • grievance redressal;

  • withdrawal of consent.

The Act therefore approaches individual control through a different rights architecture.

Key conceptual distinction

The GDPR's Article 21 model is based significantly on:

ongoing objection to processing.

The DPDP framework does not replicate that mechanism in equivalent general form.

This is an important distinction when comparing the two regimes.

46. Implications of the Difference

The difference has practical consequences.

Under GDPR Article 21, an individual may, in the circumstances covered by the provision, challenge continued processing because of his or her particular situation.

This recognises that:

A processing activity that was acceptable yesterday may become inappropriate today because the individual's circumstances have changed.

Example

A person may initially have no objection to a particular form of profiling. Later, the person's circumstances change. The person may then exercise the relevant right to object where Article 21 applies. The GDPR therefore provides a concept ofdynamic informational autonomy. Under the DPDP framework, an individual generally relies on other rights and mechanisms, such as:

  • withdrawal of consent where applicable;
  • correction;

  • erasure;

  • grievance redressal.

The practical result is that the two frameworks do not provide identical mechanisms for ongoing control over processing.

47. Critical Evaluation of Article 21

Article 21 is one of the GDPR's most important provisions concerning individual control over personal-data processing.

Its significance comes from the fact that it recognises that data protection cannot depend solely upon whether processing was initially lawful.

Individuals may have legitimate reasons to demand that particular processing stop.

The provision therefore adds a dynamic dimension to data protection.

47.1 Strength: Dynamic Protection

The GDPR recognises that circumstances can change.

A person may initially accept or tolerate processing but later develop a reason to object.

Article 21 allows the law to respond to this changing relationship.

This is particularly important for:

  • behavioural profiling;

  • online advertising;

  • AI systems;

  • data analytics.

47.2 Strength: Strong Marketing Protection

Article 21(2) provides particularly strong protection against unwanted direct marketing.

The individual does not have to prove harm.

The individual does not have to provide a justification.

The individual simply objects.

This is a powerful recognition of personal autonomy in the commercial environment.

47.3 Strength: Human-Centred Approach

Article 21 places the individual at the centre of certain processing decisions.

It recognises that:

Lawful processing is not necessarily processing that the individual must accept indefinitely.

This distinction is important.

A controller may have a lawful basis for processing, but the GDPR may nevertheless provide the individual with a mechanism to challenge or terminate particular processing.

47.4 Strength: AI Relevance

Article 21 is particularly relevant as AI-driven profiling becomes widespread.

AI systems can:

  • infer characteristics;

  • predict behaviour;

  • classify individuals;

  • personalise advertising;

  • analyse patterns;

  • make recommendations.

The right to object can therefore function as an important element of human control over algorithmic processing.

It does not solve every AI governance problem, but it contributes to the broader principle that individuals should retain meaningful control over how their personal data are used.

48. Limitations of Article 21

Despite its importance, Article 21 is not without limitations.

48.1 Complexity

The legal structure of Article 21 can be difficult for ordinary individuals to understand.

A person may need to distinguish between:

  • Article 21(1);

  • Article 21(2);

  • Article 21(3);

  • Article 21(6);

  • legitimate interests;

  • consent;

  • contractual necessity;

  • legal obligations.

This complexity may undermine practical accessibility.

A right that exists legally but cannot be understood easily may be difficult to exercise effectively.

48.2 Enforcement Difficulty

In cases falling under Article 21(1), controllers may seek to justify continued processing by relying upon their legitimate interests.

This can make disputes highly fact-specific.

The controller may argue that:

  • the processing is necessary;

  • the organisation has an important legitimate interest;

  • the processing is proportionate;

  • safeguards reduce the impact;

  • the individual's interests do not override the controller's interests.

The individual may therefore face difficulty challenging the controller's assessment.

48.3 Limited Application of Article 21(1)

Article 21(1) is not a universal objection right.

The provision is specifically linked to processing based upon:

  • public-interest grounds under Article 6(1)(e);

  • legitimate interests under Article 6(1)(f).

Therefore, the Article 21(1) mechanism does not simply allow a person to object to every processing activity.

Example

where processing is necessary for:

  • performance of a contract;

  • compliance with a legal obligation;

Article 21(1) is not the appropriate general mechanism.

Other GDPR rights may nevertheless be relevant depending upon the circumstances.

48.4 Lack of Harmonised Standards

The phrase:

"compelling legitimate grounds"

is inherently fact-sensitive.

What constitutes a compelling legitimate ground may depend upon:

  • the nature of the processing;

  • the type of personal data;

  • the individual's reasonable expectations;

  • the consequences of processing;

  • the scale of processing;

  • the safeguards implemented;

  • the relationship between the controller and individual.

This can create uncertainty.

Two controllers processing similar information might reach different conclusions regarding the strength of their interests.

The eventual assessment may therefore depend significantly upon supervisory authorities or courts.

Overall Legal Significance of Article 21

Article 21 should ultimately be understood as a provision concerned with continuing individual control over personal-data processing.

Its importance can be reduced to several central propositions.

First

Lawfulness of processing does not always mean that processing must continue indefinitely.

Second

Individuals have a specific right to object to certain processing based on their circumstances.

Third

Direct marketing receives particularly strong protection.

Fourth

Profiling connected to direct marketing falls within the protection of Article 21(2).

Fifth

The right must be communicated clearly and prominently.

Sixth

Digital systems should facilitate the exercise of the right rather than create unnecessary procedural barriers.

Seventh

Research and public-interest processing receive special treatment because the GDPR recognises the societal value of such activities.

Eighth

Article 21 has growing importance in AI governance because AI systems increasingly depend upon profiling, behavioural analysis and predictive inference.

Ninth

The GDPR and India's DPDP Act take materially different approaches to the concept of an ongoing right to object.

The broader philosophy of Article 21 is therefore one of informational autonomy:

the individual should not merely have rights at the moment data are collected; in appropriate circumstances, the individual should retain meaningful power to challenge how those data continue to be used.